This update for osslsigncode fixes the following issues:
- Update to 2.13 (boo#1260680, CVE-2025-70888):
* fixed integer overflows when processing APPX compressed data streams
* fixed double-free vulnerabilities in APPX file processing
* fixed multiple memory corruption issues in PE page hash computation
- Changes from 2.12:
* fixed a buffer overflow while extracting message digests
- Changes from 2.11:
* added keyUsage validation for signer certificate
* added printing CRL details during signature verification
* implemented a workaround for CRL servers returning the HTTP
Content-Type header other than application/pkix-crl
* fixed HTTP keep-alive handling
* fixed macOS compiler and linker flags
* fixed undefined BIO_get_fp() behavior with BIO_FLAGS_UPLINK_INTERNAL
- update to 2.10:
* added JavaScript signing
* added PKCS#11 provider support (requires OpenSSL 3.0+)
* added support for providers...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2026-115=1
- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):
osslsigncode-2.13-bp156.2.3.1
https://www.suse.com/security/cve/CVE-2025-70888.html
https://bugzilla.suse.com/1260680
Get the latest Linux and open source security news straight to your inbox.